INTEL_REPORT
Krebs on Security · published 5/18/2026, 8:48:21 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
CISA Admin Leaked AWS GovCloud Keys on Github Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregiou…
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github
sha256:069673fdbb9a74784d89220e94ea16fb8bcf565db25051389c4330a362179d76
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| domain | aws-workspace-firefox-passwords.csv | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.